A network defender's guide to threat detection: Using Zeek, Elasticsearch, Logstash, Kibana, Tor, and more
CyberSecurity Summary - En podcast af CyberSecurity Summary

Kategorier:
A comprehensive guide for network defenders. It focuses on threat detection and network analysis using a suite of open-source tools. Key components covered include the installation and configuration of Zeek (Bro) IDS, the Elastic Stack (ELK) for log analysis and visualization, and the Tor network for anonymity and traffic analysis. The guide details steps for setting up these tools on a Linux system, discusses configuring signatures for threat detection, and demonstrates how to create dashboards in Kibana to visualize network activity and potential security issues. The author, Richard Medlin, shares his experience and provides practical, step-by-step instructions for building a functional Security Information and Event Management (SIEM) setup.You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cyber_security_summaryGet the Book now from Amazon:https://www.amazon.com/network-defenders-guide-threat-detection-ebook/dp/B0899J5MND?&linkCode=ll1&tag=cvthunderx-20&linkId=f0ad2aff6e425e0b4cf3217df6ccd946&language=en_US&ref_=as_li_ss_tl